All fixes

Stop caching authenticated pages

cache-auth-page

A page carrying session data without no-store can be kept by a CDN or proxy and handed to the next visitor. Mark authenticated responses private.

Why this matters

A page with authentication data (cookies or auth headers) doesn't prevent shared caching. Proxies or CDNs could store and serve your users' private sessions to other visitors.

Cloudflare

  1. 1 Create a Cache Rule to bypass cache for authenticated paths
  2. 2 Or set Cache-Control: private at the origin
Cloudflare docs

Does your app still have this?

Scan your domain